Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

JINX-0164 Targeting virtual currency companies with fake recruiting lure and macOS malware

Lithium-ion battery fires are rapidly increasing. Firefighting technology is struggling to catch up

ESA begins fundraising for space application projects

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » JINX-0164 Targeting virtual currency companies with fake recruiting lure and macOS malware
Identity

JINX-0164 Targeting virtual currency companies with fake recruiting lure and macOS malware

By May 28, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 28, 2026Supply chain attacks/malware

A new campaign, orchestrated by a previously undocumented threat actor, targets crypto organizations with the goal of facilitating the theft of digital assets using recruitment-themed social engineering and custom-built macOS malware.

“These campaigns utilized advanced social engineering techniques, custom macOS malware, and deep targeting of CI/CD infrastructure,” said Wiz researchers Shira Ayal, Eden Abergil, Andre Maccarone, Yuval Dunn, and Benjamin Reed. “The techniques used allowed the attacker to move laterally from the compromised employee’s laptop to code distribution systems and development infrastructure.”

Google’s cloud security company is tracking this activity under the name JINX-0164. This threat actor has been active since at least mid-2025 and has been assessed for financial gain, targeting developers through recruiting themes and other social engineering techniques to siphon cryptocurrencies. In at least one case, adversaries are said to have carried out supply chain attacks.

The attack chain documented by Wiz shows JINX-0164 leveraging trusted LinkedIn profiles to approach victims and offer virtual meetings. The meeting invitation is designed to direct the target to a fraudulent domain masquerading as a teleconferencing provider.

From there, victims are tricked into downloading and installing the program. This triggers the acquisition of a Python-based macOS infostealer and remote access Trojan codenamed AUDIOFIX using a bash script hosted on a fake driver store domain (‘apple.driver-store’).[.]com”).

” [bash] The script downloaded an architecture-aware payload from the same domain that is compatible with both Intel and Apple Silicon systems. The payload masqueraded as a system audio driver named coreaudiod, was saved as ChromeUpdater, and was executed via launchctl,” Wiz said.

It then leverages Python malware to steal sensitive data from compromised endpoints, move laterally to internal code distribution systems and development infrastructure by injecting AUDIOFIX payloads, and modify source code in order to compromise other endpoints and steal cryptocurrency wallet credentials.

Captured data includes credentials from password managers, web browsers, and iCloud Keychain files. Local administrator credentials. SSH key. configuration file. Console history file. Cryptocurrency browser extension information. Cryptocurrency wallet address. Active Discord, Slack, and Telegram sessions.

In addition to information theft, AUDIOFIX supports several commands that allow manual reconnaissance, extraction, execution of arbitrary shell commands, deletion of files, and retrieval of payloads from external servers.

JINX-0164 has also been observed targeting software developers by impersonating recruiters while using the same social engineering techniques. That is, they use the opportunity to set up a meeting where they display a fake technical error and instruct the victim to download a “fix” that leads to the installation of malware.

Another key component in a threat actor’s arsenal is the MiniRAT. This is a Go-based backdoor that was previously distributed via a compromised version of an npm package named @velora-dex/sdk, a legitimate DeFi toolkit used for token swaps, limit orders, and delta trading on the VeloraDEX decentralized exchange platform.

According to details shared by SafeDep and StepSecurity last month, the compromised version downloaded a shell script from a remote server and then distributed a macOS-specific binary called MiniRAT. The malware has the ability to upload files, execute arbitrary shell commands, and obtain additional payloads and tools from attacker-controlled domains.

It is notable that some aspects of the campaign, coupled with the use of VPN services such as Astrill VPN and the focus on cryptocurrencies and developers, are reminiscent of those used by multiple North Korean threat clusters such as BlueNoroff, Contagious Interview, and UNC1069. However, Wiz said that at this stage there is no overlap in the infrastructure connecting JINX-0164 and Pyongyang.

“Similarly, while the types of spoofed domains are similar to those used by other North Korean threat actors, JINX-0164’s infrastructure has no overlap with other publicly tracked North Korean groups,” With said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLithium-ion battery fires are rapidly increasing. Firefighting technology is struggling to catch up

Related Posts

Grandoreiro malware and BTMOB RAT campaign targets Windows and Android users

May 27, 2026

Malicious npm package stole files from Claude AI user directory via GitHub

May 27, 2026

5 steps to manage shadow AI tools without degrading employee performance

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

JINX-0164 Targeting virtual currency companies with fake recruiting lure and macOS malware

Lithium-ion battery fires are rapidly increasing. Firefighting technology is struggling to catch up

ESA begins fundraising for space application projects

Google engineer who made $1.2 million from Polymarket charged with insider trading

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.